CVE-2025-5148 is a critical deserialization vulnerability in FunAudioLLM InspireMusic, specifically within the load_state_dict function of the inspiremusic/cli/model.py file. This flaw allows for local manipulation, potentially leading to compromise of confidentiality, integrity, and availability. While rated as Medium severity (CVSS 5.3), it requires local access and low privileges to exploit. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| FunAudioLLM | InspireMusic | bf32364bcb0d136497ca69f9db622e9216b029ddCNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.